Bridgeway Benefit Technologies logo
Bridgeway Benefit Technologies

Leader in technology solutions for the Taft-Hartley industry.

Associate Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteMid LevelTeam 201-500H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

5 days ago

Salary

0

Seniority

Mid Level

Bachelor Degree1 yr expEnglishCloudDockerKubernetesSDLC

Job Description

Associate Security Engineer

Bridgeway Benefit Technologies

• Assist in designing and implementing scalable and reliable security solutions with guidance from senior engineers. • Assist in developing and implementing infrastructure-as-code (IaC) solutions to enforce security policies and automate cloud configurations. • Support the maintenance and enhancement of CI/CD pipelines, automate repetitive tasks, and help improve system efficiency. • Collaborate closely with development and platform engineering teams to support their security needs. • Actively seek mentorship from senior engineers and share learnings with peers. • Complete smaller tasks independently and contribute to mid-level and larger-scale security projects with senior guidance. • Assist in maintaining SIEM solutions and log ingestion pipelines to support monitoring, alerting, and threat detection. • Assist in developing incident response playbooks for various alert types and participate in related testing to help ensure operational readiness. • Monitor emerging threats and assist in operationalizing threat intelligence tools, including alert mapping using the MITRE ATT&CK framework. • Support vulnerability management and cloud security posture management, including code/dependency scanning, WAF, and DLP configurations. • Collaborate with application teams to implement enterprise app governance and mobile application management (MAM). • Assist in developing and applying hardening guidelines for cloud workstations and servers, and in reviewing firewall rules, network security groups, and domain controllers, to help ensure secure configurations. • Collaborate with product teams to integrate security into SDLC and feature design reviews. • Support the review of customer and vendor contract security clauses under senior guidance. • Assist in coordinating phishing simulations, security awareness campaigns (e.g., KnowBe4), and coaching initiatives, helping deliver guidance and training materials to employees. • Assist in coordinating third-party penetration testing efforts to support mobile and web app security. • Help maintain compliance documentation for customers and vendors, and contribute to network diagrams and dataflow documentation with other teams. • Participate in an on-call rotation, providing timely response to security incidents outside regular business hours as needed.

Job Requirements

  • 1+ years of professional engineering experience and a familiarity with information security
  • Foundational knowledge of cloud platforms
  • Basic proficiency in scripting and automation
  • Basic understanding of version control
  • Intermediate proficiency with IaC and CI/CD pipeline tools
  • Basic understanding of containerization and orchestration concepts (e.g., ECS, ACA, K8s, Docker)
  • Strong analytical and troubleshooting skills with the ability to identify critical issues and escalate with recommendations
  • Bachelors in Information Technology, Software Development, or related field

Benefits

  • This is a remote position with preference given to East Coast candidates.

Related Categories

Related Job Pages

More Security Engineer Jobs

Team8 logo

Security-Forward Deployed AI Engineer

Team8

Global fund that builds and invests in companies in cyber, AI, fintech, and digital health.

Full TimeRemoteTeam 51-200Since 2014H1B No Sponsor

• Work directly with fraud investigators, analysts, contact center teams, and executives to understand workflows and operational challenges • Configure, customize, and optimize Charm's AI agents to match each customer's fraud operations, policies, and processes • Build integrations with customer systems, data sources, and enterprise applications • Rapidly prototype creative solutions for customer-specific requirements • Analyze production usage, identify opportunities for improvement, and continuously evolve customer deployments • Act as a trusted technical advisor throughout the customer's AI fraud transformation journey • Travel regularly to customer sites across the United States for workshops, deployments, training, and executive sessions

California
Full TimeRemoteTeam 11-50Since 2021

• Own the System Security Plan (SSP), POA&M, and all ATO documentation maintained in eMASS • Manage the full RMF lifecycle under NIST SP 800-37 Rev. 2 and NIST SP 800-53 Rev. 5, including annual control assessments and continuous monitoring • Serve as primary liaison with the VA ISSO, Security Controls Assessor, and Authorizing Official • Maintain HSPD-12/PIV compliance (IAL3/AAL3/FAL3) and VA IAM/MPI integration; ensure all personnel access meets PIV requirements within 10 business days of award • Coordinate FISMA and HIPAA compliance controls across all platform tenant applications; manage control inheritance documentation for sub-authorizations • Lead Fortify, Nessus, and continuous compliance monitoring; partner with DevSecOps Director to enforce ATO controls at the pipeline level • Maintain the Incident Response Plan (IRP) and Disaster Recovery Plan (DRP); lead annual tabletop exercises • Maintain the Policy Change Register; distribute VA policy, NIST guidance, and TRM updates within 24 hours of receipt

Florida
Full TimeRemoteTeam 51-200Since 2020

• Help develop and carry out the iOS team research strategy by doing vulnerability research, reverse engineering and exploit development on iOS. • Provide unbiased insights and ideas to the research team. • Develop proof-of-concept code and exploits to the quality standard of DFSEC. • Remain on top of various developments related to iOS such as new security mitigations, new features, etc.

United States
Full TimeRemoteTeam 51-200Since 2020

• Help develop and carry out the Web team research strategy by conducting vulnerability research and exploit development on Web Applications. • Provide unbiased insights and ideas to the web research team. • Develop proof-of-concept code and exploits. • Remain on top of various developments related to Web Technologies such as security mitigations, new features, exploitation techniques, etc.

United States